
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14936 is a stack-based buffer overflow vulnerability in NSF Unidata NetCDF-C that allows remote attackers to execute arbitrary code on affected installations. The flaw exists within the parsing of attribute names, where user-supplied data is copied to a fixed-length stack-based buffer without proper length validation. It was discovered by researcher Fady Osman, reported to the vendor on June 3, 2025, and published as a 0-day advisory on December 18, 2025, after the vendor failed to release a patch. The CVE was formally published on December 23, 2025, and carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), rooted in the absence of input length validation during attribute name parsing in NetCDF-C file processing (ZDI Advisory). An attacker crafts a malicious NetCDF file (or a web page that triggers file parsing) containing an oversized attribute name, which overflows a fixed-length stack buffer when copied, potentially overwriting the return address or other control-flow data. Exploitation requires user interaction — specifically, the target must open a malicious file or visit a malicious page that triggers NetCDF-C parsing. The attack vector is local (the file must be processed on the victim's machine), with low attack complexity and no privileges required (ZDI Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive data accessible to the user, modify or destroy files, or crash the application. While the scope is unchanged (no sandbox escape implied), the code execution primitive could serve as a foothold for further lateral movement within a network if the affected user has elevated privileges or access to shared resources (ZDI Advisory).
This vulnerability was published as a 0-day advisory by the Zero Day Initiative on December 18, 2025, meaning no vendor patch was available at the time of public disclosure (ZDI Advisory). No evidence of in-the-wild exploitation or threat actor attribution has been reported. The EPSS score is approximately 0.046%, indicating a low probability of near-term exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No public proof-of-concept exploit code beyond the ZDI advisory details has been identified.
.nc (NetCDF) files in user download directories, temporary folders, or email attachment staging areas; newly created executable files or scripts in user-writable directories following NetCDF file parsing.cmd.exe, powershell.exe, /bin/sh, curl, wget) immediately after opening a .nc file; application crashes or abnormal termination of NetCDF-parsing processes.As of the 0-day advisory publication date (December 18, 2025), no vendor patch was available from NSF Unidata for NetCDF-C (ZDI Advisory). The only recommended mitigation from ZDI is to restrict interaction with the NetCDF-C library and avoid opening untrusted NetCDF files. Organizations should implement strict file-origin controls, disable automatic parsing of NetCDF files from untrusted sources, and apply application allowlisting to limit which processes can invoke NetCDF-C. Users should monitor the NSF Unidata GitHub repository for patch releases and apply updates immediately when available.
The Zero Day Initiative published the advisory as a 0-day after an extended disclosure timeline spanning over six months, during which the vendor acknowledged the report but did not release a fix (ZDI Advisory). ZDI's decision to publish without a patch highlights ongoing challenges in coordinated disclosure with scientific software maintainers. No significant public commentary from the broader security community or media coverage beyond the ZDI advisory and standard vulnerability database aggregators has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."